Broken Keycloak redirects behind a TLS-terminating reverse proxy usually mean that three URL owners disagree: Keycloak's public hostname, the proxy's forwarded request identity, and the application's callback URI. Capture the first wrong scheme, host, port, or path; then repair the layer that created it. Changing every proxy ...